#ParsedReport
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
www.antiy.cn
畅捷通0day勒索攻击事件关联归因及产品解决方案
畅捷通T+软件的0day漏洞,被“魔笛”黑客组织利用进行勒索攻击活动,引起较大社会影响,安天CERT畅捷通0day对该勒索攻击事件关联归因,并提供了包括云主机防护、端点防护、应用防火墙等产品在内的综合解决方案。
#ParsedReport
31-08-2022
Securonix Threat Labs Security Advisory:New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems. Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems
Actors/Campaigns:
Red_delta
Threats:
Dnscat2_tool
Lolbin
Dns_tunneling_technique
Plugx_rat
TTPs:
Tactics: 7
Technics: 14
IOCs:
Url: 2
File: 6
Path: 10
IP: 3
Registry: 1
Domain: 9
Hash: 4
Softs:
windows registry, microsoft office, curl
Algorithms:
base64, rot25, rot1, xor
Win API:
WmiCreateProcess
Languages:
golang
YARA: Found
31-08-2022
Securonix Threat Labs Security Advisory:New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems. Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems
Actors/Campaigns:
Red_delta
Threats:
Dnscat2_tool
Lolbin
Dns_tunneling_technique
Plugx_rat
TTPs:
Tactics: 7
Technics: 14
IOCs:
Url: 2
File: 6
Path: 10
IP: 3
Registry: 1
Domain: 9
Hash: 4
Softs:
windows registry, microsoft office, curl
Algorithms:
base64, rot25, rot1, xor
Win API:
WmiCreateProcess
Languages:
golang
YARA: Found
Securonix
Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images…
Learn about the GO#WEBBFUSCATOR malware attack campaign, leveraging James Webb images and Office macros, and discover mitigation strategies.
#ParsedReport
31-08-2022
Asbit: An Emerging Remote Desktop Trojan. Introduction
https://blogs.juniper.net/en-us/threat-research/asbit-an-emerging-remote-desktop-trojan
Threats:
Asbit_rat
Tightvnc_tool
Geo:
Pacific, Chinese, China, Asia
IOCs:
Domain: 6
IP: 11
Path: 3
Hash: 9
File: 7
Url: 3
Softs:
discord, net framework
Algorithms:
gzip
31-08-2022
Asbit: An Emerging Remote Desktop Trojan. Introduction
https://blogs.juniper.net/en-us/threat-research/asbit-an-emerging-remote-desktop-trojan
Threats:
Asbit_rat
Tightvnc_tool
Geo:
Pacific, Chinese, China, Asia
IOCs:
Domain: 6
IP: 11
Path: 3
Hash: 9
File: 7
Url: 3
Softs:
discord, net framework
Algorithms:
gzip
Juniper Networks
Introduction
Introduction Juniper Threat Labs is currently monitoring an emerging Chinese Remote Desktop Trojan called Asbit. It’s a remote access Trojan being advertised on its developer’s website as a “Fast
#ParsedReport
31-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
chromium, windows defender, windows installer
Algorithms:
base64
Platforms:
x86
31-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
chromium, windows defender, windows installer
Algorithms:
base64
Platforms:
x86
#ParsedReport
31-08-2022
APT-C-08 wmRAT. Detailed analysis report
https://mp.weixin.qq.com/s/IZNl6N2K1LUU7e1hT4JeYw
Actors/Campaigns:
Manlinghua
Threats:
Wmrat
Industry:
Government
Geo:
Asian
IOCs:
File: 4
Hash: 13
IP: 1
Softs:
curl
31-08-2022
APT-C-08 wmRAT. Detailed analysis report
https://mp.weixin.qq.com/s/IZNl6N2K1LUU7e1hT4JeYw
Actors/Campaigns:
Manlinghua
Threats:
Wmrat
Industry:
Government
Geo:
Asian
IOCs:
File: 4
Hash: 13
IP: 1
Softs:
curl
#ParsedReport
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
https://gist.github.com/Aviadg/e10696f3a215a577585433b0854ccb31#file-pypi\_phishing-csvCheckmarx
First Known Phishing Attack Against PyPi Users
A few hours ago, PyPi disclose information on the first seen phishing attack aimed at a Python contributor. Right now, we are aware of hundreds of malicious packages that were related to this attack based on the known indicator.
#ParsedReport
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github - ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github ASEC
#ParsedReport
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea - ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea ASEC
#ParsedReport
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
ASEC
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object) - ASEC
The ASEC analysis team has recently discovered a VBScript that downloads a malicious HWP file. The distribution path of malware is yet to be determined, but the VBScript is downloaded through curl. The commands discovered so far are as follows: curl -H ”user…
#ParsedReport
01-09-2022
ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)
https://asec.ahnlab.com/en/38379
Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Energy, Financial, Transport
Geo:
Korea, Emirates
IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
01-09-2022
ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)
https://asec.ahnlab.com/en/38379
Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Energy, Financial, Transport
Geo:
Korea, Emirates
IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC
ASEC Weekly Malware Statistics (August 22nd, 2022 – August 28th, 2022) - ASEC
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 22nd, 2022 (Monday) to August 28th, 2022 (Sunday). For the main category, info…
#ParsedReport
01-09-2022
ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)
https://asec.ahnlab.com/en/38170
Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Financial
Geo:
Korea
TTPs:
IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
01-09-2022
ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)
https://asec.ahnlab.com/en/38170
Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Financial
Geo:
Korea
TTPs:
IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 15th, 2022 - August 21st, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 15th, 2022 (Monday) to August 21st, 2022 (Sunday). For the main category, info…
#ParsedReport
01-09-2022
ASEC (20220822 \~ 20220828). ASEC Weekly Malware Statistics (20220822 \~ 20220828)
https://asec.ahnlab.com/ko/38197
Threats:
Agent_tesla
Azorult
Redline_stealer
Beamwinhttp_loader
Postealer
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Financial, Energy, Transport
Geo:
Emirates, Korea
IOCs:
File: 44
Domain: 16
IP: 3
Email: 6
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
01-09-2022
ASEC (20220822 \~ 20220828). ASEC Weekly Malware Statistics (20220822 \~ 20220828)
https://asec.ahnlab.com/ko/38197
Threats:
Agent_tesla
Azorult
Redline_stealer
Beamwinhttp_loader
Postealer
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Financial, Energy, Transport
Geo:
Emirates, Korea
IOCs:
File: 44
Domain: 16
IP: 3
Email: 6
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220822 ~ 20220828) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 22일 월요일부터 8월 28일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 41.0%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 31.8%, 다운로더 21.4%, 랜섬웨어 5.8%로 집계되었다. Top 1 – Agent Tesla 인포스틸러…
#ParsedReport
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
#ParsedReport
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
Cybereason
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
Ragnar Locker is a ransomware family with security evasion capabilities which is targeting the energy sector and recently claimed to have breached DESFA, a Greek pipeline company...
#ParsedReport
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
Security Intelligence
Raspberry Robin and Dridex: Two Birds of a Feather
Explore in-depth analysis on the Raspberry Robin worm, tying it to Russia-based cybercriminal group 'Evil Corp' — the same group behind the Dridex Malware.
#ParsedReport
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
Cyble
Cyble - Highly Evasive Magecart JavaScript Skimmer Active In The Wild
Cyble Research and Intelligence Labs analyzes a highly-evasive Magecart Javascript skimmer that is active in the wild.
#ParsedReport
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
Wmcglobal
Threat Actor "Robin Banks" Phishing Kit Revisions
In July, a report was released spotlighting a threat actor known as Robin Banks. WMC Global was tracking this threat actor and noticed the scammer's...
#ParsedReport
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
#ParsedReport
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
SentinelOne
PyPI Phishing Campaign | JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
A new threat actor is spreading infostealer malware through targeted attacks on developers and fraudulent cryptotrading applications.